[infra] autopublisher dependency not pinned
Open
type-infra
- Dominant language
- Dart
- Stars
- 275
- Forks
- 144
- Avg merge
- 2d 9h
- Merged PRs (30d)
- 52
Description
https://github.com/dart-lang/native/blob/c64e9c87e1979b5a9e0de481f8d2d0ea950882b0/.github/workflows/publish.yaml#L14
@devoncarew Should we be pinning this with a Git hash instead of relying on the latest available?
Contributor guide
Research direction
Open .github/workflows/publish.yaml at line 14 and inspect the autopublisher dependency reference. Pin that dependency to a Git hash, then verify the workflow references the pinned revision; done means it no longer relies on the latest available version.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- github-actions
- Domain
- ci-cd, devops
- Issue type
- Refactor
- Difficulty
- 1/5
- Estimated time
- Under an hour
- Activity status
- Stale
- Clarity
- Clearly specified
- Newbie friendliness
- 45/100